Decoding AI Assurance: Why One Governance Framework Isn't Enough
Artificial Intelligence | ISO 42001
Published: Oct 2, 2026
If you're building or deploying AI systems, you've likely heard of the numerous governance acronyms flying around, including ISO 42001, EN 18286, AIUC-1. What you may not realize is that each framework addresses a specific purpose, so you likely need to comply with more than one.
At the recent Responsible AI Summit, Danny Manimbo, Managing Principal of Schellman's AI and ISO Services, broke down what these frameworks are and why they are complementary, not competitive, of each other. In a landscape where AI governance is shifting, evolving, and still finding its footing, this distinction matters more for your AI compliance roadmaps than you may realize.
ISO 42001, EN 18286, and AIUC-1 Explained
ISO 42001, EN 18286, and AIUC-1 each address a specific purpose in AI governance, and together, they complement each other to cover the full assurance picture.
What is ISO 42001?
ISO 42001 is an international standard for governing an AI Management System (AIMS) across the AI lifecycle. It is a voluntary compliance framework that applies to any organization providing, developing, or using AI.
ISO 42001 is governance-focused, rather than a technical audit, meaning it requires proving your organization has the systems, processes, and culture to manage AI responsibly.
ISO 42001 compliance requirements cover:
- Policies and governance roles
- AI risk and impact assessment
- Data quality and lifecycle management
- Human oversight controls
- Incident response procedures
- Internal audit and review
ISO 42001 is composed of 38 controls across 10 clauses and is certifiable through accredited bodies. ISO 42001 compliance requires continuous operation with a 3-year certificate term and annual surveillance audits.
Notably, Schellman is the first ANAB-accredited certification body in the world for ISO 42001, with major organizations like OpenAI, Anthropic, AWS, CrowdStrike, and Oracle already certified.
What is EN 18286?
EN 18286 was approved on July 12, 2026, as the EU's first harmonized standard for AI compliance. It maps directly to Article 17 of the EU AI Act's Quality Management System (QMS) requirements and is designed for organizations placing high-risk AI systems on the EU market (and those planning to).
EN 18286 is expected to be published in the EU Official Journey sometime in Q4 2026 or Q1 2027, with conformity assessments expecting to begin throughout 2027-2028. Certification schemes are still being established.
EN 18286 covers:
- AI governance and policies
- Risk identification and mitigation
- AI lifecycle controls
- Post-market monitoring
- Documentation and traceability
- Supplier oversight
EN 18286 is the first of ~10 harmonized standards being published for AI Act compliance and it specifically addresses the Quality Management System (QMS) component of EU AI Act compliance, which is just one piece of the puzzle. Once more of the EU AI Act harmonized standards are published, they will collectively represent an EU AI Act conformity assessment.
Importantly, it shares the same Clauses 4-10 structure as ISO 42001 and ISO 9001, so organizations with existing ISO programs have a significant head start.
What is AIUC-1?
AIUC-1 is the standard for AI agent security, safety, and reliability. It's a technical framework based on real-world incident testing and adversarial methods built for organizations building or deploying AI agents.
AIUC-1 is unique in that it comprehensively covers production risks that AI agents actually face and involves thorough adversarial testing and technical implementation controls. The standard is updated quarterly based on the latest research and real-world AI incidents.
The dimensions AIUC-1 addresses:
- Security: Defend against adversarial attacks, jailbreaks, prompt injections
- Data & Privacy: Protect against data leakage, IP theft, unauthorized use
- Safety: Mitigate harmful outputs, protect brand reputation
- Reliability: Prevent hallucinations and unpredictable behavior
- Accountability: Clear governance and oversight structures
- Society: Prevent broader societal harm
AIUC-1 operationalizes leading frameworks including ISO 42001, EU AI Act, NIST AI RMF, OWASP Top Ten, MITRE ATLAS, and CSA AICM. It bridges governance frameworks and actual agent performance.
Schellman is the first accredited auditor for AIUC-1 and certified the first company against AIUC-1 in March 2026. Though the program is still in the early adoption phase, this is the phase where early movers are creating market demand as AIUC-1 is still largely a competitive differentiator.
AIUC-1 As an Insurance Enabler
Insurance companies backing AI systems need confidence that organizations are proactively managing risks. AIUC-1 provides that confidence through rigorous, recurring technical validation. This is creating two interesting market dynamics:
- Insurance as an outcome: Organizations that achieve AIUC-1 certification have an easier time negotiating AI liability insurance rates.
- Frequency as a feature: The quarterly update cadence of AIUC-1 (vs. annual for traditional frameworks) reflects the pace at which new AI risks emerge and research evolves.
The Comparison Matrix: ISO 42001, EN 18286, and AIUC-1
| Dimension | ISO 42001 | EN 18286 | AIUC-1 |
| Created by | ISO/IEC international standards body | CEN-CENELEC (JTC 21) | AIUC consortium of enterprise security leaders |
| Purpose | Governance framework for responsible AI risk management | QMS mapped to EU AI Act Article 17 obligations | Technical testing & safeguards based on real-world incidents |
| Focus | Organization-level: policies, lifecycle, oversight | EU system-level: risk management, documentation, post-market monitoring | Agent-level: hallucinations, jailbreaks, data leaks, harmful outputs |
| Structure | AIMS framework (clauses 4-10) + 38 Annex A controls | QMS framework (clauses 4-10) | ~50 prescriptive requirements across 6 principles |
| Deliverable | Certification with scope statement & validity dates | Documented QMS evidence; formal schemes still forming | Certification + detailed audit report with technical testing results |
| Audit frequency | Annual surveillance (years 2-3), recertification year 4 | Not yet defined, expected to mirror annual/surveillance cycles | Quarterly technical testing + annual operational review |
| Certificate term | 3 years | Not yet defined | 12 months |
Why Compliance with One AI Governance Framework Isn't Enough
Organizations need to be proactive in showing they're invested in responsible AI and being proactive means covering the full spectrum from governance, to compliance, and technical behavior.
Each framework answers a different question for a different stakeholder:
- ISO 42001: handles organization governance and risk management.
- EN 18286: addresses regulatory compliance (particularly EU AI Act requirements).
- AIUC-1: proves your systems actually perform safely under real-world conditions.
Your board wants governance proof, regulators want compliance proof, and your customers want reliability proof. A single framework simply can't deliver all three.
How to Choose Which AI Compliance Framework to Pursue
Your context determines which frameworks you may need:
Internation Operations + Governance Focus: ISO 42001
If you operate globally or need a management system foundation for any AI program, it's best practice to start with ISO 42001 as your baseline. It's internationally applicable, recognized, and increasingly table stakes in B2B relationships.
EU Market + High-Risk Systems: ISO 42001 + EN 18286
If you have high-risk systems on the EU market and need proof of both governance and Article 17 compliance, the combination of ISO 42001 and EN 18286 demonstrates you're commitment to responsible AI through documented systems and risk controls aligned to regulatory expectations.
Agents in Production: ISO 42001 + AIUC-1
If you have AI agents in production, ISO 42001 combined with AIUC-1 provide a comprehensive compliance program. And if you operate in the EU, it's worth considering all three frameworks. AIUC-1 fills any gap in proving your agents are safe by demonstrating your systems behave reliably under real-world conditions through adversarial testing and continuous monitoring.
Real-World Example of a Global Payment Processor's Comprehensive AI Governance Program
To bring this to life, consider a global payment processor operating in the EU with high-risk AI systems for payment authorization, fraud detection, and credit risk assessment. Here's what a complete assurance picture would look like:
-
ISO 42001 compliance proves you have a real, operating management system, including AI governance for all ML/fraud systems, risk registers documenting model drift, controls for training data quality, and incident response procedures for failed authorizations. Compliance with ISO 42001 demonstrates organizational maturity and due diligence that internal audit, leadership, and investors, amongst other stakeholders, care about.
- EN 18286 proves your compliance with EU AI Act Article 17 high-risk obligations, covering Annex III classification as essential services, risk assessment mapped to payment authorization/fraud systems, lifecycle controls and documentation, and post-market monitoring plan. Compliance with EN 18286 shows proactive regulatory alignment, which matters most to EU financial regulations, including ECB and national competent authorities. As additional EU AI Act harmonized standards are published, you’ll layer in compliance with those subject areas. Starting with EN 18286 now positions you well for that evolution.
- AIUC-1 proves your systems behave reliably under real-world conditions with autonomous agent testing to ensure fraud detection escalates correctly, adversarial tests on classifier robustness, and to confirm payment blocks avoid false positives that damage customer experience. Compliance with AIUC-1 provides the technical reassurance that risk mitigation actually works in production, which merchant partners, payment networks, and customers all care most about.
Each framework answers a different question. Regulators need Article 17 proof. Merchants need reliability proof. You need governance proof. Together, they form a complete assurance picture.
Trust Through Rigor with ISO 42001, EN 18286, and AIUC-1
The three frameworks together accomplish something none can do alone: they establish organizational credibility across governance, compliance, and technical performance.
In a landscape where AI incidents make headlines and regulators are watching closely, certification provides the validation to prove that you've done the work to manage it responsibly.
For organizations just beginning their AI assurance journey, the question isn't "which framework should we choose?" It's "which frameworks do we need based on our market, use cases, and stakeholders?"
The answer is almost always: more than one. To learn more about any of these frameworks or to discuss where your AI governance program currently stands or how to develop it further, contact us today.
In the meantime, discover additional helpful AI governance roadmap insights in these resources:
About Danny Manimbo
Danny Manimbo is a Principal at Schellman based in Denver, Colorado, where he leads the firm’s Artificial Intelligence (AI) and ISO services and serves as one of Schellman’s CPA principals. In this role, he oversees the strategy, delivery, and quality of Schellman’s AI, ISO, and broader attestation services. Since joining the firm in 2013, Danny has built more than 15 years of expertise in information security, data privacy, AI governance, and compliance, helping organizations navigate evolving regulatory landscapes and emerging technologies. He is also a recognized thought leader and frequent speaker at industry conferences, where he shares insights on AI governance, security best practices, and the future of compliance. Danny has achieved the following certifications relevant to the fields of accounting, auditing, and information systems security and privacy: Certified Public Accountant (CPA), Certified Information Systems Security Professional (CISSP), Certified Information Systems Auditor (CISA), Certified Internal Auditor (CIA), Certificate of Cloud Security Knowledge (CCSK), and Certified Information Privacy Professional – United States (CIPP/US).